# Http input on different pipeline breaks beats pipeline

**URL:** <https://discuss.elastic.co/t/http-input-on-different-pipeline-breaks-beats-pipeline/220416>\
**Category:** Beats\
**Created:** [February 21, 2020, 4:25pm UTC](https://discuss.elastic.co/t/http-input-on-different-pipeline-breaks-beats-pipeline/220416 "2020-02-21T16:25:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dris](https://avatars.discourse-cdn.com/v4/letter/d/e19b73/32.png) [@dris](https://discuss.elastic.co/u/dris)\
**Post date:** [February 21, 2020, 4:25pm UTC](https://discuss.elastic.co/t/http-input-on-different-pipeline-breaks-beats-pipeline/220416/1 "2020-02-21T16:25:04Z")

</div>

I have two pipelines for logstash:

- beats
- http

When I only use beats, everything works fine, data comes in as it should. However, when I turn on the http pipeline, http starts fine, but beats throws this error:  
:exception=\>#\<LogStash::ConfigurationError: Cipher `TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384` is not available\>, :backtrace=\>["/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-beats-6.0.8-java/lib/logstash/inputs/beats.rb:174:in `create_server'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-beats-6.0.8-java/lib/logstash/inputs/beats.rb:162:in `register'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:200:in `block in register_plugins'", "org/jruby/RubyArray.java:1800:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:199:in `register_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:304:in `start\_inputs'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:260:in `start_workers'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:154:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:109:in `block in start'"], "pipeline.sources"=\>["/etc/logstash/conf.d/beats.conf"], :thread=\>"#\<Thread:0x6f92e866 run\>"}

http doesn't use SSL. Beats does.

---

<div class="post-metadata">

**Author:** ![dris](https://avatars.discourse-cdn.com/v4/letter/d/e19b73/32.png) [@dris](https://discuss.elastic.co/u/dris)\
**Post date:** [February 21, 2020, 6:25pm UTC](https://discuss.elastic.co/t/http-input-on-different-pipeline-breaks-beats-pipeline/220416/2 "2020-02-21T18:25:37Z")

</div>

Okay, figured this out so posting here for posterity:

For some reason, when running both of those inputs (separate pipelines, same logstash instance), the default cypher defaults to TLS\_ECDHE\_ECDSA\_WITH\_AES\_256\_CBC\_SHA384 and errors out.

For me, only beats was erroring out, so I proactively set:  
cipher\_suites =\> "TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256"  
as part of the input config for beats and it resolved itself without bare metal rebuilds or anything like that.

Hope it helps

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 20, 2020, 8:25pm UTC](https://discuss.elastic.co/t/http-input-on-different-pipeline-breaks-beats-pipeline/220416/3 "2020-03-20T20:25:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
